Adobe has released critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing 17 vulnerabilities that could enable arbitrary code execution, privilege escalation, bypass of security features, denial-of-service attacks, and memory exposure.
This update, tracked as APSB26-90 and published on August 11, 2026, has been rated Priority 1 by Adobe, indicating that organizations should prioritize remediation as urgent.
At the time of publication, Adobe stated that there were no known instances of these vulnerabilities being exploited in the wild.
Adobe ColdFusion Critical Vulnerabilities
The updates affect ColdFusion 2025 versions 2025.0.11 and earlier, as well as ColdFusion 2023 versions 2023.0.22 and earlier, across all supported platforms.
Administrators are advised to upgrade ColdFusion 2025 deployments to version 2025.0.12 and ColdFusion 2023 deployments to version 2023.0.23.
Given the breadth and severity of these vulnerabilities, patching is especially crucial for internet-facing ColdFusion servers, which often host business applications, administrative portals, and database-connected workloads.
The most serious vulnerability, CVE-2026-48362, is an OS command injection flaw rated CVSS 10.0. This vulnerability arises from the improper neutralization of special elements used in operating system commands, allowing unauthenticated remote attackers to execute arbitrary code.
Its CVSS vector indicates low attack complexity, no required privileges or user interaction, and a high impact on confidentiality, integrity, and availability.
If exploited, this vulnerability could enable an attacker to execute operating system commands within the context of the ColdFusion service account, potentially leading to application compromise, data theft, lateral movement, or destructive activities.
Adobe also addressed CVE-2026-48273, a critical eval injection vulnerability with a CVSS score of 9.9. Although exploitation requires low privileges, it can still lead to arbitrary code execution with significant impacts on confidentiality, integrity, and availability.
Another notable issue, CVE-2026-71384, is an incorrect authorization vulnerability rated 9.6 that can lead to an application denial-of-service.
The bulletin acknowledges three researchers for their contributions: Anirudh Anand (aka a0xnirudh) for CVE-2026-71386, Matan Sandori (aka matans1) for CVE-2026-71384, and Brennan D. St. John (aka brennanstjohn) for CVE-2026-71387.
The bulletin highlights several authorization failures, input validation weaknesses, cryptographic issues, and a heap-based buffer overflow.
While some vulnerabilities may require local access, elevated privileges, user interaction, or adjacent-network positioning, they should not be considered low-priority in enterprise environments.
Attack chains can combine authentication weaknesses, security control bypasses, and code execution flaws, increasing the impact after initial access.
Adobe noted that, effective August 11, 2026, it may assign a single CVE identifier to internally discovered vulnerabilities that share the same severity rating and CWE category when releases include systemic fixes.
As such, security teams should consider the fixes as potential remediation for multiple related code paths rather than assuming each CVE represents a single isolated defect.
In addition to patching, Adobe recommends using the latest compatible MySQL Java connector, updating to the ColdFusion JDK/JRE LTS release, reviewing serial filter protections against insecure deserialization, and following the ColdFusion Security documentation and relevant Lockdown Guide recommendations.
Administrators should prioritize inventorying exposed instances, testing and deploying the update through change-control processes, restricting access to the ColdFusion Administrator, reviewing service account privileges, and monitoring logs for anomalous command executions, authentication activities, or unexpected application errors.
CVE Details
| CVE | CWE / Vulnerability category | Impact | Severity | CVSS |
|---|---|---|---|---|
| CVE-2026-48362 | CWE-78 OS command injection | Arbitrary code execution | Critical | 10.0 |
| CVE-2026-48273 | CWE-95 Eval injection | Arbitrary code execution | Critical | 9.9 |
| CVE-2026-71384 | CWE-863 Incorrect authorization | Application denial-of-service | Critical | 9.6 |
| CVE-2026-71386 | CWE-79 Cross-site scripting | Arbitrary code execution | Critical | 8.8 |
| CVE-2026-71387 | CWE-863 Incorrect authorization | Arbitrary code execution | Critical | 8.8 |
| CVE-2026-21273 | CWE-20 Improper input validation | Privilege escalation | Critical | 8.7 |
| CVE-2026-71385 | CWE-863 Incorrect authorization | Security feature bypass | Critical | 8.4 |
| CVE-2026-34635 | CWE-321 Hard-coded cryptographic key | Security feature bypass | Critical | 8.2 |
| CVE-2026-48440 | CWE-122 Heap-based buffer overflow | Arbitrary code execution | Critical | 8.1 |
| CVE-2026-21279 | CWE-20 Improper input validation | Security feature bypass | Critical | 8.1 |
| CVE-2026-25652 | CWE-863 Incorrect authorization | Privilege escalation | Critical | 7.8 |
| CVE-2026-48386 | CWE-327 Broken or risky cryptographic algorithm | Memory exposure | Critical | 7.5 |
| CVE-2026-71383 | CWE-863 Incorrect authorization | Security feature bypass | Important | 7.3 |
| CVE-2026-48375 | CWE-863 Incorrect authorization | Application denial-of-service | Important | 6.5 |
| CVE-2026-48376 | CWE-116 Improper encoding or escaping of output | Security feature bypass | Important | 5.4 |
| CVE-2026-48384 | CWE-20 Improper input validation | Security feature bypass | Important | 4.9 |
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world





